← Zurück zur CVE-Suche

CVE-2026-61438

PraisonAI

Beschreibung

PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.

CVSS 7.3EPSS 0.202%Risiko 0.74
Quelle öffnen
Veröffentlicht
2026-07-15 12:18:18
Betroffene Versionen
<4.6.78
Typ
Kritische Software
Vektor
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H